Security experts have raised the risk assessment to medium on the recently discovered [email protected] worm, also known as Mydoom.bb, after receiving reports that the infection is spreading in the wild.
According to McAfee's Avert antivirus team, more than 50 reports of the virus being stopped or infecting users from the field have been recorded. Most of these reports have arrived from the US, though Avert has also received reports from Australia and the UK.
Mydoom.bb is similar to previous variants with a mass-mailing worm constructing messages using its own SMTP engine. It contains a peer-to-peer propagation routine and may be a .exe file. In common with other mutants it also downloads the BackDoor-CEB.f Trojan and spoofs the 'from' address.
Users are advised to be "very wary" and should most likely delete any email containing the following headers:
Message could not be delivered
Mail System Error - Returned Mail
Delivery reports about your e-mail
Returned mail: see transcript for details
Returned mail: Data format error
The virus constructs messages from pools of strings it carries in its body. After being executed, Mydoom.bb copies itself into the Windows System directory, and the worm installs itself as JAVA.EXE in the directory.
It will show Windows Explorer listening on TCP Port 1034, the port on which the web server runs. More information can be found here.
Cotton seedling freezes to death as Chang'e-4 shuts down for the Moon's 14-day lunar night
Fortnite easily out-earns PUBG, Assassin's Creed Odyssey and Red Dead Redemption 2 in 2018
Meteor showers as a service will be visible for about 100 kilometres in all directions
Saturn's rings only formed in the past 100 million years, suggests analysis of Cassini space probe data
New findings contradict conventional belief that Saturn's rings were formed along with the planet about 4.5 billion years ago